CVE-2026-56841: SQL Injection
Published Jul 2, 2026
·Updated
A malicious actor with access to the network and low privileges could exploit an authenticated SQL Injection vulnerability found in UniFi Protect Application to escalate privileges on the host device.
Affected Software
2 affected components
UniFi Protect Application
UI Unifi Protect<7.1.83
Event History
Jul 2, 2026
CVE Published
via MITRE·02:50 PM
Data Sourced
via MITRE·02:50 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-56841?
The severity of CVE-2026-56841 is rated high with a score of 8.8.
2
How do I fix CVE-2026-56841?
To fix CVE-2026-56841, update the UniFi Protect Application to the latest version provided by the vendor.
3
What type of vulnerability is CVE-2026-56841?
CVE-2026-56841 is an authenticated SQL Injection vulnerability.
4
Who is affected by CVE-2026-56841?
Users of the UniFi Protect Application with network access and low privileges are at risk from CVE-2026-56841.
5
What can an attacker do with CVE-2026-56841?
An attacker leveraging CVE-2026-56841 could escalate privileges on the host device.